← Return to Main Page /

Legal Documents, Licenses & Compliance Center

Explore our open-source licenses, privacy terms, acceptable use policies, and statutory compliance cross-references across all four software platforms.

🏛️ Federal Standard

NIST AI RMF 1.0 (SP 1270)

National Institute of Standards and Technology Artificial Intelligence Risk Management Framework governing autonomous agent risk identification, measurement, and runtime mitigations.

Official NIST SP 1270 Reference
🇪🇺 Regulation 2024/1689

EU Artificial Intelligence Act

Articles 9 (Risk Management), 14 (Human Oversight) & 15 (Technical Robustness & Cybersecurity) architectural design objectives for continuous inline proxy containment and adversarial testing.

Official EU AI Act Text
🛡️ AppSec Benchmark

OWASP GenAI Top 10 (2025)

Open Web Application Security Project framework mitigating LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, and LLM06 Excessive Agency.

Official OWASP Standard
🔌 Interoperability RFC

Model Context Protocol (MCP)

Open specification defining secure JSON-RPC bidirectional streaming between IDE language models, development tools, and reverse proxy token engines.

Official MCP Specification
📊 Formal Theorem

Differential Privacy Foundations

Rigorous $(\epsilon, \delta)$-differential privacy bounds based on Dwork & Roth formalisms, enforcing Laplace calibrated noise ($\epsilon \in [0.1, 1.5]$) and $K \ge 50$ anonymity.

Privacy Theorem (Dwork & Roth PDF)
🔐 Hardware Root-of-Trust

Apple Secure Enclave Security

Hardware-isolated coprocessor architecture using non-exportable P-256 elliptic curve keys and cryptographic batch attestation for untampered telemetry verification.

Apple Secure Enclave Guide
Layer-2 Protocol RFC

BOLT #11 Lightning Invoicing

Basis of Lightning Technology standard for non-custodial cryptographic invoice settlement, dynamic multi-hop routing, and sub-second micro-payout execution.

BOLT-11 Protocol RFC
🌱 ESG & Resilience

EU DORA, NIS2 & CSRD

Digital operational resilience standards, strict jurisdictional data residency boundary locking, ASHRAE thermal bounds, and verified Scope 2 carbon reduction telemetry.

EU DORA Resilience Framework

Laboratory Legal, Terms & Regulatory Policies Hub

Select any software platform or category to preview policies, terms, data licenses, and security targets across our software systems.

🔍
Policy Directory 17 Documents

Standards & Statutory Compliance Matrix

Architectural alignment and runtime enforcement mechanisms engineered into each software system across recognized regulatory frameworks.

🔍
Platform & Standard Statutory Clause / Reference Enforcement Mechanism Status & Policy
🔒 Confidential Security & Vulnerability Reporting

Ward Agentic R&D operates a strict coordinated vulnerability disclosure protocol. All disclosures are encrypted in transit and routed directly to core maintainers via GitLab Confidential Issues.

GitLab Confidential Ingress E2E Encrypted < 24h Triage Target

How to Report a Confidential Issue on GitLab

Follow this standardized 4-step disclosure protocol using GitLab's native confidential issue and work item framework:

STEP 1 Select Repository

Choose the affected prototype repository below to navigate to its official GitLab codebase.

STEP 2 Create New Issue

From the project left sidebar, navigate to Plan → Issues (or Work items) and click New issue.

STEP 3 Enable Confidentiality

Check "This issue is confidential" to seal the report and restrict visibility exclusively to project maintainers.

STEP 4 Submit PoC & Details

Detail the attack vector, CVSS severity estimate, and minimal reproduction steps, then click Create issue.

Select Prototype Repository to File Disclosure:
🌐 Continuum Studio
WardAgentic/continuum-studio
Open Repo ↗
⚡ DataPeer
WardAgentic/datapeer_dashboard
Open Repo ↗
🛡️ Drydock AI
WardAgentic/drydock-ai
Open Repo ↗
🌱 GreenZero
WardAgentic/greenzero
Open Repo ↗
🛡️ Safe Harbor Commitment

Security research conducted in good faith under this policy is authorized. We will not pursue legal action against researchers adhering to coordinated disclosure.

Policy: ISO/IEC 29147 Aligned
⚡ Response Targets
< 24h
Initial Triage Ack
< 72h
Critical Patch Window

Direct engineering triage by core systems maintainers. Patches are regression-tested in private testbed fleets prior to public release.